CVE-2023-36748: Weak Encryption
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The affected devices are configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data passed over to and from the affected device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RUGGEDCOM ROX MX5000to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX MX5000REto a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1400to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1500to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1501to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1510to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1511to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1512to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1524to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX1536to a version that resolves this vulnerability.Fixed in V2.16.0 - Upgrade
Upgrade
RUGGEDCOM ROX RX5000to a version that resolves this vulnerability.Fixed in V2.16.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-36748.
What is the severity of CVE-2023-36748?
The severity of CVE-2023-36748 is medium.
Which software versions are affected by CVE-2023-36748?
All versions of RUGGEDCOM ROX MX5000, RUGGEDCOM ROX MX5000RE, RUGGEDCOM ROX RX1400, RUGGEDCOM ROX RX1500, RUGGEDCOM ROX RX1501, and RUGGEDCOM ROX RX1510 prior to V2.16.0 are affected.
How can I fix the vulnerability CVE-2023-36748?
To fix the vulnerability CVE-2023-36748, you should update the affected software versions to V2.16.0 or later.
Where can I find more information about CVE-2023-36748?
You can find more information about CVE-2023-36748 at the following reference link: [Reference](https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf)